OPS-17 Logging and Monitoring - Availability of the Monitoring Software
Monitor the system components used for logging and monitoring themselves, and report their failures automatically and promptly to the responsible departments so the loss of visibility is assessed and the required action
4
artefacts
4
held by a system
0
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Heartbeat or watchdog configuration that detects a stalled log collector · SIEM / log platform
- Incident record for a monitoring outage with detection and restoration times · Backup / DR tooling
- Availability report for the monitoring platform itself · SIEM / log platform
- Log volume trend showing collection gaps and their explanation · SIEM / log platform
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
none for this control
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- The monitoring platform watched by nothing, so its own outage passes in silence
- Agents that stop sending without any absence alert being generated
- Collector storage exhaustion dropping events with no notification
- No defined maximum acceptable blind period during a monitoring failure
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetOPS-16 Logging and Monitoring - Configuration · OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept